CVE-2009-4370

Drupal Core <6.15 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

Scores

EPSS 0.0016
EPSS Percentile 36.2%

Classification

CWE
CWE-79
Status published

Affected Products (24)

drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 9 more

Timeline

Published Dec 21, 2009
Tracked Since Feb 18, 2026